CVE-2024-9381 is a path traversal vulnerability in Ivanti Cloud Services Appliance (CSA) versions prior to 5.0.2, allowing a remote authenticated attacker with administrative privileges to bypass security restrictions. This vulnerability carries a high CVSS score of 7.2, indicating a significant risk of complete compromise of confidentiality, integrity, and availability. While no public exploit code or KEV listing exists, the vulnerability has garnered substantial community discussion and media coverage, with Ivanti itself warning of its exploitation in attacks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.0.2CPE matchmatch criteria | cpe:2.3:a:ivanti:endpoint_manager_cloud_services_appliance:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.